Description
Magic Iso Maker 5.5 build 281 contains a buffer overflow vulnerability in the Serial Code registration field that allows local attackers to crash the application by submitting an oversized input. Attackers can generate a file containing 5000 bytes of data, paste it into the Serial Code field during registration, and trigger a denial of service condition that crashes the application.
Problem types
Product status
Credits
Alejandra Sánchez
References
www.exploit-db.com/exploits/46656 (ExploitDB-46656)
www.magiciso.com (Official Product Homepage)
www.magiciso.com/Setup_MagicISO.exe (Product Reference)
www.vulncheck.com/...maker-buffer-overflow-denial-of-service (VulnCheck Advisory: Magic Iso Maker 5.5 Buffer Overflow Denial of Service)